Impact
A flaw in the a high‑privileged attacker who can reach the system over HTTP to compromise the application. The vulnerability is easily exploitable and results in the attacker gaining full control of the service, effectively enabling remote code execution and administrative takeover. This is a Broken Access Control (CWE‑284) flaw. The CVSS vector indicates a high impact on confidentiality, integrity, and availability. It can also affect additional Oracle Fusion Middleware products due to a scope change.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These are components of Oracle Fusion Middleware and are used in enterprise capture workflows.
Risk and Exploitability
The CVSS score of 9.1 reflects critical severity, but the EPSS score of less than 1% indicates that the vulnerability is not widely exploited yet. It is not currently listed in CISA’s KEV catalog. The attack requires network access to the HTTP interface of the Client Bundle and a privileged attacker; once accessed, the attacker the application. This vulnerability represents a Broken Access Control flaw (CWE‑284) that permits privilege escalation.
OpenCVE Enrichment